Access to Cloud IoT Core is secured with IAM. Let's have a look at the list of predefined roles, together with a short description for each:
- Cloudiot Viewer: This has read-only access to all Cloud IoT resources.
- Cloudiot Device Controller: This has access to update the configuration of devices. It does not have rights to create or delete devices.
- Cloudiot Provisioner: This has rights to create and delete devices from registries but not to modify the registries.
- Cloudiot Editor: This has read-write access to all Cloud IoT resources.
- Cloudiot Admin: This has full control of all Cloud IoT resources and permissions.